Skip to content

evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) - #6152

Merged
jonahgabriel merged 6 commits into
devfrom
auto/occ-observation-drift-occ-observations-omninode-ai--omnimarket-pr-2024-38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8--v1--run31062523818-1-yaml
Aug 9, 2026
Merged

jonahgabriel merged 6 commits into
devfrom
auto/occ-observation-drift-occ-observations-omninode-ai--omnimarket-pr-2024-38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8--v1--run31062523818-1-yaml

Conversation

@onexbot-occ-writer

Copy link
Copy Markdown
Contributor

Deterministic, append-only OCC observation record authored by node_occ_observation_effect. Adds exactly one net-new file: drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml.

Implements OMN-14888
Evidence-Ticket: OMN-14888

node-occ-observation-effect added 2 commits August 6, 2026 06:59
…niNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml
@jonahgabriel
jonahgabriel force-pushed the auto/occ-observation-drift-occ-observations-omninode-ai--omnimarket-pr-2024-38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8--v1--run31062523818-1-yaml branch from 79befab to c8bec95 Compare August 6, 2026 11:02
@jonahgabriel jonahgabriel added the ci:ready Full CI runs on this PR (OMN-15731 label-gated CI pilot) label Aug 9, 2026
@jonahgabriel
jonahgabriel merged commit 77795c2 into dev Aug 9, 2026
97 of 98 checks passed
@jonahgabriel
jonahgabriel deleted the auto/occ-observation-drift-occ-observations-omninode-ai--omnimarket-pr-2024-38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8--v1--run31062523818-1-yaml branch August 9, 2026 07:19
jonahgabriel added a commit that referenced this pull request Aug 9, 2026
…4994a03a479ac90f__v1__run31292255084-1.yaml) (#6240)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/2cea83b3d664a5a3a919d4e14994a03a479ac90f__v1__run31292255084-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31292255084-1

* evidence(OMN-15763): OCC companion for omnimarket PR #2027 (#6239)

* evidence(OMN-15763): OCC companion for omnimarket PR #2027

Falsifiable deploy-gate evidence (OMN-14505 sense) for the seam registry +
canonical seam-projection serialization PR: three live GitHub-content
probes against the PR head commit (canonical.py's canonical_sha256,
node_seam_match_compute's HandlerSeamMatch, and seams.v1.yaml's
schema_version header), plus the standard self-bind check. All three
probes verified locally against the PR head SHA
6bbd87de3c0173956969f5a0b159c8631e4b929e before committing.

Rebuilt on origin/dev (onex_change_control's live default branch — main
now accepts only promotion/hotfix PRs, discovered live via
main-target-guard on the first attempt against main). Net-new-file-only.

OMN-15763

* fix(OMN-15763): buffer check_value producers to avoid Rule E SIGPIPE false-RED

OMN-15411 Rule E (contract corpus ratchet) caught 3 new sigpipe-fragile
instances: gh api <contents> --jq .content | base64 -d | grep -q ... is a
measured SIGPIPE-fragile shape (141/0/141/0/141 across 5 runs against real
inputs) — grep -q exits at the first match and closes its stdin, base64 -d
is killed by SIGPIPE, and dod_verify's bash -o pipefail turns that 141 into
a false RED on evidence that is actually present.

Rewrote all three live-content probes to the buffered-read form:
body="$(<producer>)" && printf '%s' "$body" | grep -qF 'MARKER'. Verified
locally: sigpipe_fragile_violation() returns None for all three (was
non-None before), all three still execute correctly under
bash -o pipefail -c against the live GitHub API, and
validate_pr_deploy_required.has_deploy_evidence() still returns True
(the buffered form still classifies as a falsifiable live-surface probe).
Also re-pinned all three refs to the omnimarket PR's final head commit
f1741be0163ab757738bb9ddbf7d2d67aca6aa49 (was 6bbd87de, superseded by the
CodeRabbit-fix commit).

OMN-15763

* evidence(OMN-15763): PASS receipts for all four dod_evidence items

occ-preflight/verify hard-required receipts under
drift/dod_receipts/OMN-15763/<item_id>/command.yaml for every item -- an
OCC PR's in-tree contract carries its own receipts (the "in-repo trap").
All four probes run for real against the omnimarket PR #2027 head commit
f1741be0163ab757738bb9ddbf7d2d67aca6aa49 and this OCC PR's own state
(#6239). contract_sha256 + contract_entry_sha256 computed via
omnibase_core.validation.validator_receipt_gate against the landed
contract (commit 5f647f0). Verified
locally end-to-end: uv run python -m
omnibase_core.validation.validator_occ_merge_eligibility against this
tree returns eligible=true, reason=eligible, zero missing_or_nonpass_receipts.

probe_stdout required a non-empty value (ModelDodReceipt: "receipts with
empty stdout are indistinguishable from probes that never ran") -- the
contract's check_value stays the buffered grep -qF form (Rule E safe,
quiet by design), while each receipt's own probe_command is the
non-quiet grep -F variant that captures the actual matched line as
real evidence.

OMN-15763

* evidence(OMN-14888): OCC observation append (b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml) (#6144)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31058937953-1

* evidence(OMN-14888): self-bind OCC observation PR 6144

* evidence(OMN-14888): make OCC self-bind 6144 append-stable

* fix(OMN-14888): repair self-bind assertion in occ-self-bind-pr-6144

Rewrite the dod_evidence check to bind PR #6144 to immutable facts
(PR number, base repo, exact head ref) and accept state open OR
closed+merged, so the check stays true after this PR merges instead
of asserting .state == "open" forever.

* fix(OMN-14888): regenerate occ-self-bind-pr-6144 receipt for repaired check_value

Bind contract_entry_sha256 to the updated dod_evidence entry hash so
the OCC merge-eligibility gate's per-entry binding check passes.

* fix(OMN-14888): supersede occ-self-bind-pr-6134 with merged-terminal-state binding

PR #6134 merged to dev (2026-08-09T03:14:53Z, ea53c31) while this PR
was in flight. Its self-bind entry asserts .state == "open" forever,
which now fails closed. Append-only supersession per the
occ-self-bind-pr-5855-superseded / occ-self-bind-pr-6149-superseded
precedent — bind to the merged-terminal state instead; the superseded
entry stays verbatim for audit.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml) (#6132)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2021/7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31054912492-1

* evidence(OMN-14888): self-bind OCC observation PR 6132

* evidence(OMN-14888): make OCC self-bind 6132 append-stable

* fix(OMN-14888): regenerate occ-self-bind-pr-6132 receipt for entry-hash match

The contract entry's check_value was rewritten to accept open OR
closed+merged terminal state (self-bind fix), which changed its
recomputed contract_entry_sha256. Regenerated the receipt with a
fresh live probe against PR #6132 and the matching entry hash so
occ-preflight eligibility passes instead of failing on
contract_hash_mismatch.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml (#6173)

* fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml

Five guard jobs carry timeout-minutes budgets below the observed latency of
the self-hosted omnibase-ci runner fleet under concurrent load. When a job
hits its own timeout wall GitHub records conclusion=cancelled, and CI Summary
(the sole required umbrella context on onex_change_control dev) compares each
needs.<job>.result against "success" fail-closed - so a guard that passed gets
scored as a violation and turns the required context red.

Raise the three 5-minute guards and the two 10-minute jobs to 20 minutes:
  - validate-prod-promotion-grants         5  -> 20
  - check-platform-leads-review-tripwire   5  -> 20
  - check-bot-authored-authz-guard         5  -> 20
  - predicate-parity                      10  -> 20
  - no-noncanonical-lifecycle-classes     10  -> 20

Not a gate weakening: every guard still runs, still must reach
conclusion=success, and CI Summary's fail-closed != "success" comparison is
untouched. Only the wall-clock budget moved.

Evidence-Ticket: OMN-15722

* evidence(OMN-15722): add OCC ticket contract + PASS receipts for guard timeout fix

The first push carried no contracts/OMN-15722.yaml, so both of the two
content-gating required contexts on this PR failed with the same single root
cause: validator_occ_merge_eligibility reported
reason=missing_contract / missing_contracts=["OMN-15722"] on
`occ-preflight / eligibility` (job 93010633789) and on `verify / verify`
step 21 "Run OCC Eligibility" (job 93010633875). Note step 7
"Resolve Evidence-Source" was SKIPPED in that same job, confirming the
in-repo Evidence-Source exemption - the missing contract was the only blocker.

Contract declares three dod_evidence items, all probed live and receipted with
real command output (no fabricated receipts):

  dod-occ-guard-timeout-budgets-raised  - substantive (L1): parses ci.yml and
    asserts all five named guard jobs declare timeout-minutes 20.
  dod-occ-guards-still-fail-closed      - substantive (L1): asserts all five
    guards remain in ci-summary's needs list, carry no continue-on-error, still
    have their literal fail-closed `result }}" != "success"` comparison in
    ci.yml, and that ci.yml still declares no top-level concurrency block.
    Falsifiability proven by negative control - rewriting the predicate-parity
    comparison to an equality form makes the same probe exit 1 with
    unguarded=['predicate-parity'].
  occ-self-bind-pr-6173                 - binding stamp only (L0), companion
    PR identity for receipt-gate binding.

Local verification: all three probes exit 0 / stdout "true"; the eligibility
validator now returns eligible=true reason=eligible
("OCC evidence is present, PASS, hash-bound, and PR-bound") with all three
receipt ids resolved. Full pre-commit over contract + receipts + ci.yml passes,
including Receipt Honesty Gate, Receipt Hardening Gate, Contract Substance
Floor, DoD-authoring hygiene, Canonical contract shape v1, and the
Evidence-Commit SHA Existence Gate.

Evidence-Ticket: OMN-15722

* evidence(OMN-15722): remove false no_source_change attestation from receipts

All three OMN-15722 receipts asserted no_source_change: true. Per
omnibase_core model_dod_receipt.py that field is RUNTIME_OPS-only and
asserts the change produced NO repo diff and NO PR. This change has a
5-line ci.yml diff and IS PR #6173, so the assertion was materially false.

These receipts carry evidence_class: None and pr_number: 6173, so the
field does not apply to them at all -- removed rather than set to false.
Its default is False, which is the truthful value. All three re-validate
against ModelDodReceipt with no_source_change=False.

Note: the model validator enforces only the RUNTIME_OPS -> True
direction, not the inverse, so a non-RUNTIME_OPS receipt asserting
no_source_change: true alongside a pr_number validates cleanly and no CI
gate would have caught this. Model gap, flagged not fixed here.

* fix(OMN-15722): widen validate-prod-promotion-grants budget to 45m (19m02s measured)

The 20m budget left that job ~58s of headroom against its measured 19m02s
runtime on PR #6173 run 31222755192 — a re-starve one contention spike away,
which is the exact defect this PR exists to remove.

Profile of the 19m02s (steps API, head 2df62fc):
  Checkout code                                 11m48s
  Run ./.github/actions/setup-uv                 5m30s
  Validate prod-promotion-grants trust anchor        2s

The work is 2 seconds; the runtime is fleet latency. Within that one run,
Checkout code for the same repo/SHA ranged 74s (omninode-runner-63) to 708s
(omninode-runner-21) — a ~9.6x contention spread — so the budget must cover the
latency tail, not the job's work. 45m is ~2.4x the worst observation.

Other four guards unchanged at 20. Contract probe updated from a flat ==20
assertion to a per-job expected-budget map so it stays falsifiable, and the
contract summary corrected (it claimed all five go to 20).

* evidence(OMN-15722): re-stamp all three receipts at head d772fb8

The prior stamps carried run_timestamp 2026-08-07T22:29:26Z / commit_sha
2df62fc, which predated both the 45m widening and the contract edit — the
receipts attested a tree that no longer existed.

All three probes were re-run against the working tree at d772fb8; none of
these values is carried over:

  dod-occ-guard-timeout-budgets-raised  exit 0, stdout 'true'
  dod-occ-guards-still-fail-closed      exit 0, stdout 'true'
  occ-self-bind-pr-6173                 exit 0, stdout 'true'

Receipt 1's probe changed with the contract: a flat 'all five == 20' assertion
would now fail, so it became a per-job expected-budget map (45/20/20/20/20).
Its contract_entry_sha256 is recomputed to
sha256:4c1ae3b62a7def4f0ca209d9921d974c6c74a4927cb8dc5fa3d4e32a99adeec8;
entries 2 and 3 are parse-identical so their hashes are unchanged.

Both substantive probes re-verified falsifiable at this head by negative
control — reverting 45->20 exits 1 with [('validate-prod-promotion-grants', 20,
45)], and flipping the predicate-parity comparison to == exits 1 with
unguarded=['predicate-parity'].

* fix(OMN-15722): uniform 45m timeout floor across all 10 budgeted ci-summary needs members

contract-shape-v1 (budget 25) was cancelled at 25m50s on this PR's own run
31222755192, cancelled step Checkout code (1358s) - the same starvation the
five already-raised guards hit. Inside that one run, for the same repo and
SHA, checkout ranged 6s-1358s and setup-uv 93s-571s, so the runner preamble
alone has been observed above 30m and every per-job budget under that is
provably insufficient. Sets 45 uniformly across all ten ci-summary needs
members that declare a timeout-minutes. Also corrects the inline fleet-size
comment: live gh api orgs/OmniNode-ai/actions/runners reports 64 runners
labelled omnibase-ci, not 48.

* evidence(OMN-15722): re-stamp all three receipts at the uniform-45m head

* docs(OMN-15722): tighten the latency claim to single-phase observations

The prior wording said the runner preamble had been observed above 30m; that
number was a cross-job sum of the worst checkout (1358s, contract-shape-v1)
and the worst setup-uv (571s, a different job), not a single observed
preamble. Replaced with the two exact single-phase observations plus the
worst own-work step among the ten budgeted gates (53s). No budget changes.

* evidence(OMN-15722): re-stamp all three receipts at 63be7d6

* evidence(OMN-15722): admissible self-bind supersedes gh-pr-view INERT check

occ-self-bind-pr-6173 uses `gh pr view`, which lexes to bare `gh` in command
position (not `gh api`) and is INADMISSIBLE (NOT_EXECUTED) under the OMN-15309
evidence_admissibility predicate. Contract Compliance Check on this PR's own
run (31228584791, job 93027660648) collapsed the whole dod_evidence
supersession chain to 0/3 PASS -> BLOCK, reddening the required check.

Append-only fix: occ-self-bind-pr-6173-admissible supersedes it with
`gh api repos/OWNER/REPO/pulls/6173/files` asserting the changed-file count
(5), with printed stdout so the run is distinguishable from a probe that
never executed (Receipt Hardening Gate, OMN-13060/OMN-15710). Verified
ADMISSIBLE by direct execution of classify_evidence over the exact
check_value, and the check itself run green (count=5) and red (count=4,
exit 1) before being recorded. Nothing above the new entries in
contracts/OMN-15722.yaml is edited; every prior dod_evidence item keeps its
bytes and OMN-13888 per-entry hash.

Local run of scripts/ci/run_contract_compliance_check.py against this head
confirms PASS (1/4 PASS, 3 WARN, 0 BLOCK).

* evidence(OMN-15722): correct stale self-bind file-count assertion (5 -> 7)

occ-self-bind-pr-6173-admissible asserted PR #6173's changed-file count
== 5, but adding its own receipt file to the diff made the live count 6
the moment it was committed -- confirmed red on Contract Compliance
Check (job 93048702548, run 31236076328): live count=6, assertion
expected 5, exit 1.

Appends occ-self-bind-pr-6173-admissible-v2, a self-inclusive correction:
its own receipt file is the 7th changed path, so it asserts count == 7,
the number that includes the file recording its own PASS.

* evidence(OMN-15722): OCC companion for #6173 (#6174)

* evidence: OCC companion pass 1 for #6173

* evidence: OCC companion self-bind for #6174

* fix(OMN-15722): format OCC autobind contract

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml) (#6149)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31061495853-1

* evidence(OMN-14888): self-bind OCC observation PR 6149

* evidence(OMN-14888): make OCC self-bind 6149 append-stable

* fix(OMN-14888): repair PR #6149 self-bind to append-only-stable predicate

The occ-self-bind-pr-6149 dod_evidence entry asserted .state == "open",
which goes false the instant this PR merges — a self-bind that breaks
append-only immutability on merge. Rebind to immutable facts (PR number,
base repo, head branch) with state accepted as open OR closed+merged,
keeping the check falsifiable for a wrong PR number/branch.

* fix(OMN-14888): supersede stale occ-self-bind-pr-6134 open-state assertion

PR #6134 merged (2026-08-09T03:14:53Z, merge commit ea53c31...) while its
merged dod_evidence entry occ-self-bind-pr-6134 still asserts .state ==
"open" -- the same class OMN-15374's occ-self-bind-pr-5855-superseded fixed
(OCC #6084 precedent). Append a net-new superseding entry bound to the
merged-terminal state; the original entry stays untouched (append-only).

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15763): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2028 (#6242)

* evidence(OMN-15763): author OCC companion for OmniNode-ai/omnimarket#2028

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 512b272bb26aba643093872519c8c46c142b0de2.

* evidence(OMN-15763): self-bind OCC#6242 + rebind contract_sha256

* fix(OMN-15763): backfill missing dod-occ-evidence-admissibility-validator contract entry

The OCC Companion Author automation emitted this receipt on PR #2028's
companion (dod-occ-evidence-admissibility-validator, node_pr_lifecycle_fix_effect
self-check) without adding the matching dod_evidence contract entry, tripping
the receipt-hardening append-only gate. Backfills the entry (source: generated,
matching the shape of the other autobind entries) and computes the real
contract_entry_sha256 via compute_contract_entry_sha256 (was a "PENDING"
placeholder) — verified locally against scripts/validation/check_receipt_hardening.py.

OMN-15763

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml) (#6138)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2023/cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31057101391-1

* evidence(OMN-14888): self-bind OCC observation PR 6138

* evidence(OMN-14888): make OCC self-bind 6138 append-stable

* fix(OMN-14888): regenerate occ-self-bind-pr-6138 receipt for self-bind fix

The self-bind entry's check_value was rewritten to bind to immutable
facts (PR#/head ref/base repo, state open OR closed+merged) so the
assertion survives merge, matching the #6132/#6144 precedent. This
changes contract_entry_sha256, so the receipt is regenerated with the
recomputed hash and a fresh live probe readback.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) (#6152)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31062523818-1

* evidence(OMN-14888): self-bind OCC observation PR 6152

* evidence(OMN-14888): make OCC self-bind 6152 append-stable

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml) (#6164)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2025/d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31142195987-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15757, OMN-15778): OCC companion for OmniNode-ai/omninode_infra#833 (#6246)

* evidence: OCC companion pass 1 for OmniNode-ai/omninode_infra#833

* evidence: OCC companion self-bind for #6246

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>

* evidence(OMN-15336): bind infra PR 2676 vendor migration (#6167)

* evidence(OMN-15336): bind infra PR 2676 vendor migration

* evidence(OMN-15336): self-bind OCC PR 6167

* evidence(OMN-15336): refresh registry RLS heads

* fix(OMN-15336): supersede market PR 2021 evidence append-only

* evidence(OMN-15336): rebind infra PR 2676 current head

* chore(OMN-15336): retrigger OCC gates

* evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2029 (#6247)

* evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2029

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5.

* evidence(OMN-15777): self-bind OCC#6247 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2030 (#6248)

* evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2030

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 271a7abe276bc6a5663599a6e7736c8faab843f7.

* evidence(OMN-15777): self-bind OCC#6248 + rebind contract_sha256

* fix(OMN-15777): revert unintended mutation of merged receipt (append-only repair)

The occ-evidence-source-autobind commit for PR #2030 (57e1628) rebound
drift/dod_receipts/OMN-15777/dod-occ-evidence-admissibility-validator/command.yaml
in place -- but that receipt already merged as part of OCC#6247 (PR #2029's
companion) and is immutable per the append-only doctrine. PR #2030 already
carries its own dedicated, net-new evidence entries
(dod-OmniNode-ai-omnimarket-pr-2030, dod-OmniNode-ai-omnimarket-pr-2030-ci,
occ-self-bind-pr-6248) that bind it to commit 271a7abe; the shared validator
receipt did not need to be re-pointed at PR #2030 to satisfy that binding.

Reverts the file to its merged-on-dev content. No supersession file is
needed -- this is not a correction to the receipt's claim (still true and
still bound to PR #2029/commit f9cc9dcc), it is an unforced touch that
should never have modified it.

Implements OMN-15777

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15780): OCC Evidence-Source autobind for OmniNode-ai/omninode_infra#834 (#6250)

* evidence(OMN-15780): author OCC companion for OmniNode-ai/omninode_infra#834

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 1fdeb0c9c9367d70e43ef88b128203cf567c4aed.

* evidence(OMN-15780): self-bind OCC#6250 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-14888): OCC observation append (023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml) (#6155)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31063872175-1

* evidence(OMN-14888): self-bind OCC observation PR 6155

* evidence(OMN-14888): make OCC self-bind 6155 append-stable

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5__v1__run31303503673-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31303503673-1

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/c11400fe9483b9face2601c391f0a73add5d52cf__v1__run31304580306-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31304580306-1

* fix(OMN-14888): repair occ-self-bind-pr-6155 receipt after dev-merge

Conflict resolution against dev landing on PR #6155 rewrote the
occ-self-bind-pr-6155 dod_evidence entry's check_value to accept the
terminal closed+merged PR state (matching the occ-self-bind-pr-6134 /
occ-self-bind-pr-6149 established pattern) instead of a bare
.state == "open" assertion that would fail closed the moment this PR
merges. That byte change moved the per-entry contract hash, so the
paired receipt is regenerated here with the recomputed
contract_entry_sha256 and a fresh live probe_stdout.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml) (#6237)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31291311120-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>
Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com>
Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Co-authored-by: omnimarket-bot <bot@omninode.ai>
jonahgabriel added a commit that referenced this pull request Aug 9, 2026
…19c8c46c142b0de2__v1__run31297664660-1.yaml) (#6243)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2028/512b272bb26aba643093872519c8c46c142b0de2__v1__run31297664660-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31297664660-1

* evidence(OMN-15722): OCC companion for #6173 (#6174)

* evidence: OCC companion pass 1 for #6173

* evidence: OCC companion self-bind for #6174

* fix(OMN-15722): format OCC autobind contract

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml) (#6149)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31061495853-1

* evidence(OMN-14888): self-bind OCC observation PR 6149

* evidence(OMN-14888): make OCC self-bind 6149 append-stable

* fix(OMN-14888): repair PR #6149 self-bind to append-only-stable predicate

The occ-self-bind-pr-6149 dod_evidence entry asserted .state == "open",
which goes false the instant this PR merges — a self-bind that breaks
append-only immutability on merge. Rebind to immutable facts (PR number,
base repo, head branch) with state accepted as open OR closed+merged,
keeping the check falsifiable for a wrong PR number/branch.

* fix(OMN-14888): supersede stale occ-self-bind-pr-6134 open-state assertion

PR #6134 merged (2026-08-09T03:14:53Z, merge commit ea53c31...) while its
merged dod_evidence entry occ-self-bind-pr-6134 still asserts .state ==
"open" -- the same class OMN-15374's occ-self-bind-pr-5855-superseded fixed
(OCC #6084 precedent). Append a net-new superseding entry bound to the
merged-terminal state; the original entry stays untouched (append-only).

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15763): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2028 (#6242)

* evidence(OMN-15763): author OCC companion for OmniNode-ai/omnimarket#2028

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 512b272bb26aba643093872519c8c46c142b0de2.

* evidence(OMN-15763): self-bind OCC#6242 + rebind contract_sha256

* fix(OMN-15763): backfill missing dod-occ-evidence-admissibility-validator contract entry

The OCC Companion Author automation emitted this receipt on PR #2028's
companion (dod-occ-evidence-admissibility-validator, node_pr_lifecycle_fix_effect
self-check) without adding the matching dod_evidence contract entry, tripping
the receipt-hardening append-only gate. Backfills the entry (source: generated,
matching the shape of the other autobind entries) and computes the real
contract_entry_sha256 via compute_contract_entry_sha256 (was a "PENDING"
placeholder) — verified locally against scripts/validation/check_receipt_hardening.py.

OMN-15763

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml) (#6138)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2023/cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31057101391-1

* evidence(OMN-14888): self-bind OCC observation PR 6138

* evidence(OMN-14888): make OCC self-bind 6138 append-stable

* fix(OMN-14888): regenerate occ-self-bind-pr-6138 receipt for self-bind fix

The self-bind entry's check_value was rewritten to bind to immutable
facts (PR#/head ref/base repo, state open OR closed+merged) so the
assertion survives merge, matching the #6132/#6144 precedent. This
changes contract_entry_sha256, so the receipt is regenerated with the
recomputed hash and a fresh live probe readback.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) (#6152)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31062523818-1

* evidence(OMN-14888): self-bind OCC observation PR 6152

* evidence(OMN-14888): make OCC self-bind 6152 append-stable

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml) (#6164)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2025/d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31142195987-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15757, OMN-15778): OCC companion for OmniNode-ai/omninode_infra#833 (#6246)

* evidence: OCC companion pass 1 for OmniNode-ai/omninode_infra#833

* evidence: OCC companion self-bind for #6246

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>

* evidence(OMN-15336): bind infra PR 2676 vendor migration (#6167)

* evidence(OMN-15336): bind infra PR 2676 vendor migration

* evidence(OMN-15336): self-bind OCC PR 6167

* evidence(OMN-15336): refresh registry RLS heads

* fix(OMN-15336): supersede market PR 2021 evidence append-only

* evidence(OMN-15336): rebind infra PR 2676 current head

* chore(OMN-15336): retrigger OCC gates

* evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2029 (#6247)

* evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2029

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5.

* evidence(OMN-15777): self-bind OCC#6247 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2030 (#6248)

* evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2030

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 271a7abe276bc6a5663599a6e7736c8faab843f7.

* evidence(OMN-15777): self-bind OCC#6248 + rebind contract_sha256

* fix(OMN-15777): revert unintended mutation of merged receipt (append-only repair)

The occ-evidence-source-autobind commit for PR #2030 (57e1628) rebound
drift/dod_receipts/OMN-15777/dod-occ-evidence-admissibility-validator/command.yaml
in place -- but that receipt already merged as part of OCC#6247 (PR #2029's
companion) and is immutable per the append-only doctrine. PR #2030 already
carries its own dedicated, net-new evidence entries
(dod-OmniNode-ai-omnimarket-pr-2030, dod-OmniNode-ai-omnimarket-pr-2030-ci,
occ-self-bind-pr-6248) that bind it to commit 271a7abe; the shared validator
receipt did not need to be re-pointed at PR #2030 to satisfy that binding.

Reverts the file to its merged-on-dev content. No supersession file is
needed -- this is not a correction to the receipt's claim (still true and
still bound to PR #2029/commit f9cc9dcc), it is an unforced touch that
should never have modified it.

Implements OMN-15777

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15780): OCC Evidence-Source autobind for OmniNode-ai/omninode_infra#834 (#6250)

* evidence(OMN-15780): author OCC companion for OmniNode-ai/omninode_infra#834

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 1fdeb0c9c9367d70e43ef88b128203cf567c4aed.

* evidence(OMN-15780): self-bind OCC#6250 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-14888): OCC observation append (023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml) (#6155)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31063872175-1

* evidence(OMN-14888): self-bind OCC observation PR 6155

* evidence(OMN-14888): make OCC self-bind 6155 append-stable

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5__v1__run31303503673-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31303503673-1

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/c11400fe9483b9face2601c391f0a73add5d52cf__v1__run31304580306-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31304580306-1

* fix(OMN-14888): repair occ-self-bind-pr-6155 receipt after dev-merge

Conflict resolution against dev landing on PR #6155 rewrote the
occ-self-bind-pr-6155 dod_evidence entry's check_value to accept the
terminal closed+merged PR state (matching the occ-self-bind-pr-6134 /
occ-self-bind-pr-6149 established pattern) instead of a bare
.state == "open" assertion that would fail closed the moment this PR
merges. That byte change moved the per-entry contract hash, so the
paired receipt is regenerated here with the recomputed
contract_entry_sha256 and a fresh live probe_stdout.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml) (#6237)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31291311120-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (2cea83b3d664a5a3a919d4e14994a03a479ac90f__v1__run31292255084-1.yaml) (#6240)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/2cea83b3d664a5a3a919d4e14994a03a479ac90f__v1__run31292255084-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31292255084-1

* evidence(OMN-15763): OCC companion for omnimarket PR #2027 (#6239)

* evidence(OMN-15763): OCC companion for omnimarket PR #2027

Falsifiable deploy-gate evidence (OMN-14505 sense) for the seam registry +
canonical seam-projection serialization PR: three live GitHub-content
probes against the PR head commit (canonical.py's canonical_sha256,
node_seam_match_compute's HandlerSeamMatch, and seams.v1.yaml's
schema_version header), plus the standard self-bind check. All three
probes verified locally against the PR head SHA
6bbd87de3c0173956969f5a0b159c8631e4b929e before committing.

Rebuilt on origin/dev (onex_change_control's live default branch — main
now accepts only promotion/hotfix PRs, discovered live via
main-target-guard on the first attempt against main). Net-new-file-only.

OMN-15763

* fix(OMN-15763): buffer check_value producers to avoid Rule E SIGPIPE false-RED

OMN-15411 Rule E (contract corpus ratchet) caught 3 new sigpipe-fragile
instances: gh api <contents> --jq .content | base64 -d | grep -q ... is a
measured SIGPIPE-fragile shape (141/0/141/0/141 across 5 runs against real
inputs) — grep -q exits at the first match and closes its stdin, base64 -d
is killed by SIGPIPE, and dod_verify's bash -o pipefail turns that 141 into
a false RED on evidence that is actually present.

Rewrote all three live-content probes to the buffered-read form:
body="$(<producer>)" && printf '%s' "$body" | grep -qF 'MARKER'. Verified
locally: sigpipe_fragile_violation() returns None for all three (was
non-None before), all three still execute correctly under
bash -o pipefail -c against the live GitHub API, and
validate_pr_deploy_required.has_deploy_evidence() still returns True
(the buffered form still classifies as a falsifiable live-surface probe).
Also re-pinned all three refs to the omnimarket PR's final head commit
f1741be0163ab757738bb9ddbf7d2d67aca6aa49 (was 6bbd87de, superseded by the
CodeRabbit-fix commit).

OMN-15763

* evidence(OMN-15763): PASS receipts for all four dod_evidence items

occ-preflight/verify hard-required receipts under
drift/dod_receipts/OMN-15763/<item_id>/command.yaml for every item -- an
OCC PR's in-tree contract carries its own receipts (the "in-repo trap").
All four probes run for real against the omnimarket PR #2027 head commit
f1741be0163ab757738bb9ddbf7d2d67aca6aa49 and this OCC PR's own state
(#6239). contract_sha256 + contract_entry_sha256 computed via
omnibase_core.validation.validator_receipt_gate against the landed
contract (commit 5f647f0). Verified
locally end-to-end: uv run python -m
omnibase_core.validation.validator_occ_merge_eligibility against this
tree returns eligible=true, reason=eligible, zero missing_or_nonpass_receipts.

probe_stdout required a non-empty value (ModelDodReceipt: "receipts with
empty stdout are indistinguishable from probes that never ran") -- the
contract's check_value stays the buffered grep -qF form (Rule E safe,
quiet by design), while each receipt's own probe_command is the
non-quiet grep -F variant that captures the actual matched line as
real evidence.

OMN-15763

* evidence(OMN-14888): OCC observation append (b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml) (#6144)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31058937953-1

* evidence(OMN-14888): self-bind OCC observation PR 6144

* evidence(OMN-14888): make OCC self-bind 6144 append-stable

* fix(OMN-14888): repair self-bind assertion in occ-self-bind-pr-6144

Rewrite the dod_evidence check to bind PR #6144 to immutable facts
(PR number, base repo, exact head ref) and accept state open OR
closed+merged, so the check stays true after this PR merges instead
of asserting .state == "open" forever.

* fix(OMN-14888): regenerate occ-self-bind-pr-6144 receipt for repaired check_value

Bind contract_entry_sha256 to the updated dod_evidence entry hash so
the OCC merge-eligibility gate's per-entry binding check passes.

* fix(OMN-14888): supersede occ-self-bind-pr-6134 with merged-terminal-state binding

PR #6134 merged to dev (2026-08-09T03:14:53Z, ea53c31) while this PR
was in flight. Its self-bind entry asserts .state == "open" forever,
which now fails closed. Append-only supersession per the
occ-self-bind-pr-5855-superseded / occ-self-bind-pr-6149-superseded
precedent — bind to the merged-terminal state instead; the superseded
entry stays verbatim for audit.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml) (#6132)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2021/7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31054912492-1

* evidence(OMN-14888): self-bind OCC observation PR 6132

* evidence(OMN-14888): make OCC self-bind 6132 append-stable

* fix(OMN-14888): regenerate occ-self-bind-pr-6132 receipt for entry-hash match

The contract entry's check_value was rewritten to accept open OR
closed+merged terminal state (self-bind fix), which changed its
recomputed contract_entry_sha256. Regenerated the receipt with a
fresh live probe against PR #6132 and the matching entry hash so
occ-preflight eligibility passes instead of failing on
contract_hash_mismatch.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml (#6173)

* fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml

Five guard jobs carry timeout-minutes budgets below the observed latency of
the self-hosted omnibase-ci runner fleet under concurrent load. When a job
hits its own timeout wall GitHub records conclusion=cancelled, and CI Summary
(the sole required umbrella context on onex_change_control dev) compares each
needs.<job>.result against "success" fail-closed - so a guard that passed gets
scored as a violation and turns the required context red.

Raise the three 5-minute guards and the two 10-minute jobs to 20 minutes:
  - validate-prod-promotion-grants         5  -> 20
  - check-platform-leads-review-tripwire   5  -> 20
  - check-bot-authored-authz-guard         5  -> 20
  - predicate-parity                      10  -> 20
  - no-noncanonical-lifecycle-classes     10  -> 20

Not a gate weakening: every guard still runs, still must reach
conclusion=success, and CI Summary's fail-closed != "success" comparison is
untouched. Only the wall-clock budget moved.

Evidence-Ticket: OMN-15722

* evidence(OMN-15722): add OCC ticket contract + PASS receipts for guard timeout fix

The first push carried no contracts/OMN-15722.yaml, so both of the two
content-gating required contexts on this PR failed with the same single root
cause: validator_occ_merge_eligibility reported
reason=missing_contract / missing_contracts=["OMN-15722"] on
`occ-preflight / eligibility` (job 93010633789) and on `verify / verify`
step 21 "Run OCC Eligibility" (job 93010633875). Note step 7
"Resolve Evidence-Source" was SKIPPED in that same job, confirming the
in-repo Evidence-Source exemption - the missing contract was the only blocker.

Contract declares three dod_evidence items, all probed live and receipted with
real command output (no fabricated receipts):

  dod-occ-guard-timeout-budgets-raised  - substantive (L1): parses ci.yml and
    asserts all five named guard jobs declare timeout-minutes 20.
  dod-occ-guards-still-fail-closed      - substantive (L1): asserts all five
    guards remain in ci-summary's needs list, carry no continue-on-error, still
    have their literal fail-closed `result }}" != "success"` comparison in
    ci.yml, and that ci.yml still declares no top-level concurrency block.
    Falsifiability proven by negative control - rewriting the predicate-parity
    comparison to an equality form makes the same probe exit 1 with
    unguarded=['predicate-parity'].
  occ-self-bind-pr-6173                 - binding stamp only (L0), companion
    PR identity for receipt-gate binding.

Local verification: all three probes exit 0 / stdout "true"; the eligibility
validator now returns eligible=true reason=eligible
("OCC evidence is present, PASS, hash-bound, and PR-bound") with all three
receipt ids resolved. Full pre-commit over contract + receipts + ci.yml passes,
including Receipt Honesty Gate, Receipt Hardening Gate, Contract Substance
Floor, DoD-authoring hygiene, Canonical contract shape v1, and the
Evidence-Commit SHA Existence Gate.

Evidence-Ticket: OMN-15722

* evidence(OMN-15722): remove false no_source_change attestation from receipts

All three OMN-15722 receipts asserted no_source_change: true. Per
omnibase_core model_dod_receipt.py that field is RUNTIME_OPS-only and
asserts the change produced NO repo diff and NO PR. This change has a
5-line ci.yml diff and IS PR #6173, so the assertion was materially false.

These receipts carry evidence_class: None and pr_number: 6173, so the
field does not apply to them at all -- removed rather than set to false.
Its default is False, which is the truthful value. All three re-validate
against ModelDodReceipt with no_source_change=False.

Note: the model validator enforces only the RUNTIME_OPS -> True
direction, not the inverse, so a non-RUNTIME_OPS receipt asserting
no_source_change: true alongside a pr_number validates cleanly and no CI
gate would have caught this. Model gap, flagged not fixed here.

* fix(OMN-15722): widen validate-prod-promotion-grants budget to 45m (19m02s measured)

The 20m budget left that job ~58s of headroom against its measured 19m02s
runtime on PR #6173 run 31222755192 — a re-starve one contention spike away,
which is the exact defect this PR exists to remove.

Profile of the 19m02s (steps API, head 2df62fc):
  Checkout code                                 11m48s
  Run ./.github/actions/setup-uv                 5m30s
  Validate prod-promotion-grants trust anchor        2s

The work is 2 seconds; the runtime is fleet latency. Within that one run,
Checkout code for the same repo/SHA ranged 74s (omninode-runner-63) to 708s
(omninode-runner-21) — a ~9.6x contention spread — so the budget must cover the
latency tail, not the job's work. 45m is ~2.4x the worst observation.

Other four guards unchanged at 20. Contract probe updated from a flat ==20
assertion to a per-job expected-budget map so it stays falsifiable, and the
contract summary corrected (it claimed all five go to 20).

* evidence(OMN-15722): re-stamp all three receipts at head d772fb8

The prior stamps carried run_timestamp 2026-08-07T22:29:26Z / commit_sha
2df62fc, which predated both the 45m widening and the contract edit — the
receipts attested a tree that no longer existed.

All three probes were re-run against the working tree at d772fb8; none of
these values is carried over:

  dod-occ-guard-timeout-budgets-raised  exit 0, stdout 'true'
  dod-occ-guards-still-fail-closed      exit 0, stdout 'true'
  occ-self-bind-pr-6173                 exit 0, stdout 'true'

Receipt 1's probe changed with the contract: a flat 'all five == 20' assertion
would now fail, so it became a per-job expected-budget map (45/20/20/20/20).
Its contract_entry_sha256 is recomputed to
sha256:4c1ae3b62a7def4f0ca209d9921d974c6c74a4927cb8dc5fa3d4e32a99adeec8;
entries 2 and 3 are parse-identical so their hashes are unchanged.

Both substantive probes re-verified falsifiable at this head by negative
control — reverting 45->20 exits 1 with [('validate-prod-promotion-grants', 20,
45)], and flipping the predicate-parity comparison to == exits 1 with
unguarded=['predicate-parity'].

* fix(OMN-15722): uniform 45m timeout floor across all 10 budgeted ci-summary needs members

contract-shape-v1 (budget 25) was cancelled at 25m50s on this PR's own run
31222755192, cancelled step Checkout code (1358s) - the same starvation the
five already-raised guards hit. Inside that one run, for the same repo and
SHA, checkout ranged 6s-1358s and setup-uv 93s-571s, so the runner preamble
alone has been observed above 30m and every per-job budget under that is
provably insufficient. Sets 45 uniformly across all ten ci-summary needs
members that declare a timeout-minutes. Also corrects the inline fleet-size
comment: live gh api orgs/OmniNode-ai/actions/runners reports 64 runners
labelled omnibase-ci, not 48.

* evidence(OMN-15722): re-stamp all three receipts at the uniform-45m head

* docs(OMN-15722): tighten the latency claim to single-phase observations

The prior wording said the runner preamble had been observed above 30m; that
number was a cross-job sum of the worst checkout (1358s, contract-shape-v1)
and the worst setup-uv (571s, a different job), not a single observed
preamble. Replaced with the two exact single-phase observations plus the
worst own-work step among the ten budgeted gates (53s). No budget changes.

* evidence(OMN-15722): re-stamp all three receipts at 63be7d6

* evidence(OMN-15722): admissible self-bind supersedes gh-pr-view INERT check

occ-self-bind-pr-6173 uses `gh pr view`, which lexes to bare `gh` in command
position (not `gh api`) and is INADMISSIBLE (NOT_EXECUTED) under the OMN-15309
evidence_admissibility predicate. Contract Compliance Check on this PR's own
run (31228584791, job 93027660648) collapsed the whole dod_evidence
supersession chain to 0/3 PASS -> BLOCK, reddening the required check.

Append-only fix: occ-self-bind-pr-6173-admissible supersedes it with
`gh api repos/OWNER/REPO/pulls/6173/files` asserting the changed-file count
(5), with printed stdout so the run is distinguishable from a probe that
never executed (Receipt Hardening Gate, OMN-13060/OMN-15710). Verified
ADMISSIBLE by direct execution of classify_evidence over the exact
check_value, and the check itself run green (count=5) and red (count=4,
exit 1) before being recorded. Nothing above the new entries in
contracts/OMN-15722.yaml is edited; every prior dod_evidence item keeps its
bytes and OMN-13888 per-entry hash.

Local run of scripts/ci/run_contract_compliance_check.py against this head
confirms PASS (1/4 PASS, 3 WARN, 0 BLOCK).

* evidence(OMN-15722): correct stale self-bind file-count assertion (5 -> 7)

occ-self-bind-pr-6173-admissible asserted PR #6173's changed-file count
== 5, but adding its own receipt file to the diff made the live count 6
the moment it was committed -- confirmed red on Contract Compliance
Check (job 93048702548, run 31236076328): live count=6, assertion
expected 5, exit 1.

Appends occ-self-bind-pr-6173-admissible-v2, a self-inclusive correction:
its own receipt file is the 7th changed path, so it asserts count == 7,
the number that includes the file recording its own PASS.

* evidence(OMN-15722): OCC companion for #6173 (#6174)

* evidence: OCC companion pass 1 for #6173

* evidence: OCC companion self-bind for #6174

* fix(OMN-15722): format OCC autobind contract

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml) (#6149)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31061495853-1

* evidence(OMN-14888): self-bind OCC observation PR 6149

* evidence(OMN-14888): make OCC self-bind 6149 append-stable

* fix(OMN-14888): repair PR #6149 self-bind to append-only-stable predicate

The occ-self-bind-pr-6149 dod_evidence entry asserted .state == "open",
which goes false the instant this PR merges — a self-bind that breaks
append-only immutability on merge. Rebind to immutable facts (PR number,
base repo, head branch) with state accepted as open OR closed+merged,
keeping the check falsifiable for a wrong PR number/branch.

* fix(OMN-14888): supersede stale occ-self-bind-pr-6134 open-state assertion

PR #6134 merged (2026-08-09T03:14:53Z, merge commit ea53c31...) while its
merged dod_evidence entry occ-self-bind-pr-6134 still asserts .state ==
"open" -- the same class OMN-15374's occ-self-bind-pr-5855-superseded fixed
(OCC #6084 precedent). Append a net-new superseding entry bound to the
merged-terminal state; the original entry stays untouched (append-only).

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15763): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2028 (#6242)

* evidence(OMN-15763): author OCC companion for OmniNode-ai/omnimarket#2028

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 512b272bb26aba643093872519c8c46c142b0de2.

* evidence(OMN-15763): self-bind OCC#6242 + rebind contract_sha256

* fix(OMN-15763): backfill missing dod-occ-evidence-admissibility-validator contract entry

The OCC Companion Author automation emitted this receipt on PR #2028's
companion (dod-occ-evidence-admissibility-validator, node_pr_lifecycle_fix_effect
self-check) without adding the matching dod_evidence contract entry, tripping
the receipt-hardening append-only gate. Backfills the entry (source: generated,
matching the shape of the other autobind entries) and computes the real
contract_entry_sha256 via compute_contract_entry_sha256 (was a "PENDING"
placeholder) — verified locally against scripts/validation/check_receipt_hardening.py.

OMN-15763

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml) (#6138)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2023/cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31057101391-1

* evidence(OMN-14888): self-bind OCC observation PR 6138

* evidence(OMN-14888): make OCC self-bind 6138 append-stable

* fix(OMN-14888): regenerate occ-self-bind-pr-6138 receipt for self-bind fix

The self-bind entry's check_value was rewritten to bind to immutable
facts (PR#/head ref/base repo, state open OR closed+merged) so the
assertion survives merge, matching the #6132/#6144 precedent. This
changes contract_entry_sha256, so the receipt is regenerated with the
recomputed hash and a fresh live probe readback.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) (#6152)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31062523818-1

* evidence(OMN-14888): self-bind OCC observation PR 6152

* evidence(OMN-14888): make OCC self-bind 6152 append-stable

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml) (#6164)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2025/d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31142195987-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15757, OMN-15778): OCC companion for OmniNode-ai/omninode_infra#833 (#6246)

* evidence: OCC companion pass 1 for OmniNode-ai/omninode_infra#833

* evidence: OCC companion self-bind for #6246

---------

Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>

* evidence(OMN-15336): bind infra PR 2676 vendor migration (#6167)

* evidence(OMN-15336): bind infra PR 2676 vendor migration

* evidence(OMN-15336): self-bind OCC PR 6167

* evidence(OMN-15336): refresh registry RLS heads

* fix(OMN-15336): supersede market PR 2021 evidence append-only

* evidence(OMN-15336): rebind infra PR 2676 current head

* chore(OMN-15336): retrigger OCC gates

* evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2029 (#6247)

* evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2029

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5.

* evidence(OMN-15777): self-bind OCC#6247 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2030 (#6248)

* evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2030

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 271a7abe276bc6a5663599a6e7736c8faab843f7.

* evidence(OMN-15777): self-bind OCC#6248 + rebind contract_sha256

* fix(OMN-15777): revert unintended mutation of merged receipt (append-only repair)

The occ-evidence-source-autobind commit for PR #2030 (57e1628) rebound
drift/dod_receipts/OMN-15777/dod-occ-evidence-admissibility-validator/command.yaml
in place -- but that receipt already merged as part of OCC#6247 (PR #2029's
companion) and is immutable per the append-only doctrine. PR #2030 already
carries its own dedicated, net-new evidence entries
(dod-OmniNode-ai-omnimarket-pr-2030, dod-OmniNode-ai-omnimarket-pr-2030-ci,
occ-self-bind-pr-6248) that bind it to commit 271a7abe; the shared validator
receipt did not need to be re-pointed at PR #2030 to satisfy that binding.

Reverts the file to its merged-on-dev content. No supersession file is
needed -- this is not a correction to the receipt's claim (still true and
still bound to PR #2029/commit f9cc9dcc), it is an unforced touch that
should never have modified it.

Implements OMN-15777

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-15780): OCC Evidence-Source autobind for OmniNode-ai/omninode_infra#834 (#6250)

* evidence(OMN-15780): author OCC companion for OmniNode-ai/omninode_infra#834

OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 1fdeb0c9c9367d70e43ef88b128203cf567c4aed.

* evidence(OMN-15780): self-bind OCC#6250 + rebind contract_sha256

---------

Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-14888): OCC observation append (023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml) (#6155)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31063872175-1

* evidence(OMN-14888): self-bind OCC observation PR 6155

* evidence(OMN-14888): make OCC self-bind 6155 append-stable

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5__v1__run31303503673-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31303503673-1

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/c11400fe9483b9face2601c391f0a73add5d52cf__v1__run31304580306-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31304580306-1

* fix(OMN-14888): repair occ-self-bind-pr-6155 receipt after dev-merge

Conflict resolution against dev landing on PR #6155 rewrote the
occ-self-bind-pr-6155 dod_evidence entry's check_value to accept the
terminal closed+merged PR state (matching the occ-self-bind-pr-6134 /
occ-self-bind-pr-6149 established pattern) instead of a bare
.state == "open" assertion that would fail closed the moment this PR
merges. That byte change moved the per-entry contract hash, so the
paired receipt is regenerated here with the recomputed
contract_entry_sha256 and a fresh live probe_stdout.

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

* evidence(OMN-14888): OCC observation append (6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml) (#6237)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31291311120-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>
Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com>
Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Co-authored-by: omnimarket-bot <bot@omninode.ai>

* evidence(OMN-14888): OCC observation append (f1741be0163ab757738bb9ddbf7d2d67aca6aa49__v1__run31293106241-1.yaml) (#6241)

* evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/f1741be0163ab757738bb9ddbf7d2d67aca6aa49__v1__run31293106241-1.yaml

* evidence(OMN-14888): OCC observation self-bind occ-observation-run31293106241-1

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>

---------

Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai>
Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com>
Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai>
Co-authored-by: Jonah Gray <jonah@omninode.ai>
Co-authored-by: omnimarket-bot <bot@omninode.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci:ready Full CI runs on this PR (OMN-15731 label-gated CI pilot)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant